Privacy policy
How we handle your data when you visit this website or get in touch – in short: sparingly. No cookies, no tracking, no third-party content.
1. The essentials
This privacy policy explains which personal data is processed when you visit berliner-autismuszentrum.de, why, and which rights you have.
- This website sets no cookies of its own and uses no analytics, tracking or advertising tools and no social media plugins.
- No third-party content is loaded: fonts, images and scripts are served from our own site.
- There is no contact form and no user accounts. You reach us by phone or e-mail.
- The website is delivered through the network of our service provider Cloudflare. This involves technically necessary connection data (section 5).
- Your language choice and your settings in the “Adjust display” menu are stored only in your browser and are never sent to us (section 6).
2. Controller
The controller responsible for data processing on this website is:
Berliner Autismus-Zentrum gUG (haftungsbeschränkt)
Düppelstraße 31
12163 Berlin, Germany
Represented by the managing director: Sahsenem Camoglu
Phone: +49 30 287 057 12
E-mail: info@berliner-autismuszentrum.de
3. Data protection officer
Our data protection officer is heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany, www.heydata.eu, datenschutz@heydata.eu.
4. General information on data processing
Legal bases
We process personal data only where a legal basis permits it. Depending on the operation, this is:
- Art. 6(1)(a) GDPR – you have given consent.
- Art. 6(1)(b) GDPR – processing is necessary to perform a contract or to take steps prior to entering into one, for example when you enquire about our services.
- Art. 6(1)(c) GDPR – we are legally obliged to, for example by retention duties.
- Art. 6(1)(f) GDPR – processing serves a legitimate interest of ours or of a third party, such as running the website securely and reliably.
- Art. 9(2) GDPR – for special categories of personal data, in particular health data, that you share with us voluntarily.
- § 25 TDDDG (the German Telecommunications Digital Services Data Protection Act) – for storing information in your browser (section 6).
We name the legal basis we rely on with each processing operation below.
Retention
We keep personal data only as long as necessary for the respective purpose. After that we delete it, unless statutory retention duties (for example under commercial or tax law, up to ten years) require longer storage. In that case processing is restricted and the data is deleted once the period has expired.
Recipients and transfers to third countries
We pass on personal data only where this is necessary for the stated purpose, where we are legally obliged to, or where you have consented. Service providers that process data on our behalf (processors, Art. 28 GDPR) are contractually bound to our instructions and to the GDPR.
Where data is transferred to countries outside the European Union, this happens only if an adequate level of data protection exists there – for instance because the company is certified under the EU-US Data Privacy Framework – or if appropriate safeguards such as the European Commission’s standard contractual clauses have been agreed. Details are given with the respective processing operations.
You can obtain a copy of the standard contractual clauses agreed in each case from us on request (contact details in section 2). The European Commission’s standard contractual clauses are also published at eur-lex.europa.eu; which companies are certified under the EU-US Data Privacy Framework can be checked at www.dataprivacyframework.gov.
No obligation to provide data
You are neither legally nor contractually obliged to provide us with personal data. However, the website cannot be delivered without the technical connection data described in section 5, and we cannot answer an enquiry without your contact details.
No automated decision-making
We make no automated individual decisions and use no profiling (Art. 22 GDPR).
5. Hosting and delivery via Cloudflare
This website runs on the platform of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (“Cloudflare”) and is delivered through its global network. Cloudflare provides the server the website runs on, speeds up delivery and protects the website against attacks, for example denial-of-service (DDoS) attacks and automated access.
Which data is involved
To deliver the website to you, Cloudflare processes technical connection data with every request. This includes:
- the IP address of the requesting device
- date and time of the request
- the requested address (URL) and the page you came from (referrer), if your browser sends it
- type and version of the browser and operating system
- amount of data transferred and the status code of the response
- the country derived from the IP address
This data is necessary to establish the connection, deliver the website and detect attacks. Cloudflare keeps it in logs for a limited period and then deletes it according to its own policies. We ourselves have no access to these logs in detail; we only see aggregated, non-personal statistics such as the number of requests per day or country. Only when Cloudflare blocks a request as an attack is the IP address concerned briefly visible to us in the security events.
We have not enabled Cloudflare’s additional logging and analytics features (Workers Logs, Logpush, Cloudflare Web Analytics).
Security checks
If Cloudflare classifies a request as suspicious, it may run a short security check before granting access. So that the check does not have to be repeated on every page view, Cloudflare may set a technically necessary cookie in your browser for this (such as “cf_clearance” or “__cf_bm”). These cookies serve security only, contain no data that could recognise you across other websites, and expire after a short time. With normal browsing there is usually no check and no cookie is set.
Legal basis and transfer to third countries
The legal basis is our legitimate interest in providing the website securely, quickly and reliably (Art. 6(1)(f) GDPR); for the security cookies additionally § 25(2) no. 2 TDDDG, as they are strictly necessary to provide the website to you.
Cloudflare processes the data as our processor on the basis of a data processing agreement under Art. 28 GDPR. As Cloudflare operates servers worldwide, data may also be processed in the USA and other countries outside the EU. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework; in addition, the European Commission’s standard contractual clauses form part of the agreement.
Further information: Cloudflare’s privacy policy and Cloudflare’s data processing addendum.
6. Cookies and local storage in your browser
This website sets no cookies of its own – not for statistics, not for advertising and not for the language choice. The only exception are the security cookies described in section 5, which Cloudflare sets in exceptional cases. Two settings are stored locally by your browser at your request:
Language choice
The language of a page is determined solely by its address. If, according to its language settings, your browser prefers one of our three languages other than the one of the page you opened, we show a notice that the page is also available in that language. This comparison takes place entirely in your browser; your language settings are not sent to us. When you pick a language or dismiss the notice, your browser remembers that decision in local storage under the entry “baz-locale” so that the notice does not appear again. Only the language code is stored, for example “en”.
Display settings
The “Adjust display” button lets you set colour scheme, motion, contrast, text size and calm colours. Your browser likewise stores this selection in local storage under the entries “baz-mode” and “baz-display” so that it still applies on your next visit.
Neither setting leaves your device: they are transmitted neither to us nor to third parties and contain nothing that identifies you. You can change them at any time through the menus or delete them via your browser’s site data.
The legal basis is § 25(2) no. 2 TDDDG: storage is strictly necessary to provide a function you have explicitly requested. No consent is needed for this.
Session storage
While you navigate within the website, your browser keeps technical details such as the scroll position in session storage so that you land in the same place after pressing “Back”. This information is used locally only and is deleted when the tab is closed.
7. Contacting us by e-mail or phone
When you write to us by e-mail or call us, we process the data you share with us: your name, your e-mail address or phone number, the content of your message and, where applicable, details about your child or the person you are enquiring for. We use this data to handle and answer your enquiry.
Legal bases
- If your enquiry concerns our services – for example a consultation or admission to autism-specific support – the legal basis is the initiation of a contract (Art. 6(1)(b) GDPR).
- For all other enquiries the legal basis is our legitimate interest in answering enquiries and communicating with you (Art. 6(1)(f) GDPR).
- Health data: enquiries to us often contain particularly sensitive details, for example about an autism diagnosis, a child’s development or behaviour, or reports from school or daycare. We process such details only insofar as you share them with us voluntarily, on the basis of your explicit consent (Art. 9(2)(a) GDPR). By sharing such details with us of your own accord, you explicitly consent to our using them to handle your enquiry. You can withdraw this consent at any time with effect for the future. For any subsequent counselling and support we inform you separately about how your data is handled, in particular under the provisions on social data protection.
A note for your safety: an ordinary e-mail is not encrypted end to end in transit. Please do not send us diagnostic reports, assessments or other sensitive documents by e-mail unless we ask you to. For a first conversation, your name, a number we can call you back on and a short description of your request are enough. You are of course also welcome to call us.
Recipients
Our mailboxes are operated by Microsoft as part of Microsoft 365 (Exchange Online). Our contractual partner is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland; the processing takes place on our behalf on the basis of a data processing agreement under Art. 28 GDPR. The contents of our mailboxes are stored and processed in data centres within the European Union (EU Data Boundary). In individual cases – for instance for support requests or for certain security and diagnostic data – access from the USA by Microsoft Corporation may nevertheless occur. Microsoft Corporation is certified under the EU-US Data Privacy Framework; in addition, the European Commission’s standard contractual clauses form part of the contract (copies on request, section 4). Further information: Microsoft privacy statement and Microsoft Products and Services Data Protection Addendum.
Within our organisation only the staff handling your enquiry have access.
Retention
We delete your enquiry once it has been fully dealt with and no further cooperation results from the contact – as a rule within twelve months at the latest. If the enquiry leads to counselling or support, the data becomes part of the respective file and is subject to the retention periods that apply to it. Business correspondence that must be kept under commercial or tax law is stored for the statutory period.
8. Job applications
When you apply to us – for an advertised position or speculatively – we process the data in your application documents: contact details, CV, cover letter, certificates and proof of qualifications, and any other details you provide. The purpose is to run the application process and decide on employment.
The legal basis is Art. 6(1)(b) GDPR in conjunction with § 26(1) of the German Federal Data Protection Act (BDSG) (establishing an employment relationship). If your documents contain special categories of personal data – for example about a severe disability or your health – we process them under Art. 9(2)(b) GDPR in conjunction with § 26(3) BDSG insofar as this is necessary for rights and duties under employment law. For work with children and young people we require an extended certificate of good conduct before employment (§ 72a SGB VIII); we will inform you about this during the process.
Only the people involved in the selection process have access to your documents. Applications sent by e-mail are stored with our e-mail provider (section 7); the note on unencrypted transmission applies here too.
If you are hired, we transfer the data to your personnel file. Otherwise we delete your documents no later than six months after the process has ended, so that we can respond to claims under the German General Equal Treatment Act. If you would like us to keep your application on file for future positions beyond that, we ask for your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
9. Links to other websites
This website contains links to other providers’ services, for example a link to Google Maps that shows our address on a map. Merely visiting our website transfers no data to these providers. Only when you click such a link do you leave our website; from then on the respective provider’s privacy policy applies. Links to external websites are marked with a corresponding icon and open in a new window.
Clicking a phone number or e-mail address opens the application set up on your device; no data flows to us in that case either.
10. Editor area
The address /admin leads to the editor area in which our staff maintain the website’s content. It is not intended for visitors and is blocked for search engines. Sign-in uses an account with the GitHub service (GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA), where the website’s content is also stored; during sign-in a short-lived, technically necessary cookie is set that protects the sign-in against misuse. This concerns only our staff, whom we inform separately. The legal basis is our legitimate interest in maintaining the website securely and traceably (Art. 6(1)(f) GDPR) and, insofar as data of our employees is concerned, section 26(1) of the German Federal Data Protection Act (BDSG). During sign-in and when content is saved, data – the signed-in person’s username, e-mail address and IP address as well as the edited content – is transferred to GitHub in the USA. GitHub, Inc. is certified under the EU-US Data Privacy Framework; in addition, the European Commission’s standard contractual clauses apply as part of the GitHub Data Protection Agreement (copies on request, section 4). Visiting the public pages transfers no data to GitHub.
11. Data security
The connection to this website is encrypted throughout with TLS (HTTPS); your browser is instructed to use encrypted connections only. Additional safeguards – including a strict Content Security Policy – prevent foreign content or scripts from being embedded in the website. We continuously adapt our technical and organisational measures to the state of the art.
12. Your rights
You have the following rights against us:
- Access (Art. 15 GDPR) to whether and which data we process about you.
- Rectification (Art. 16 GDPR) of inaccurate or incomplete data.
- Erasure (Art. 17 GDPR), unless a retention duty or another reason stands against it.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR): to receive the data you provided to us in a common, machine-readable format.
- Withdrawal of consent (Art. 7(3) GDPR) at any time with effect for the future; the lawfulness of processing carried out until then remains unaffected.
Right to object
Where we process your data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you have the right to object to the processing at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
(Berlin Commissioner for Data Protection and Freedom of Information)
Alt-Moabit 59–61
10555 Berlin, Germany
Phone: +49 30 13889-0
E-mail: mailbox@datenschutz-berlin.de
www.datenschutz-berlin.de
How to exercise your rights
Write to us informally at info@berliner-autismuszentrum.de or by post to the address given in section 2. So that we do not hand data to unauthorised persons, we may ask you to confirm your identity. We reply as quickly as possible and within one month at the latest.
13. Children and young people
Our services are for children and young people; the website, however, is aimed at their parents and guardians and at professional organisations. We do not request data from children through the website and do not knowingly collect it. When you, as a parent or guardian, share details about your child with us, we treat them with particular care (section 7).
14. Changes to this privacy policy
We update this privacy policy when the website or the legal situation changes – for example if we introduce a contact form or a statistics tool. The version published here applies; the date of the last change is shown at the end of the page.
Last updated: